J2Commerce Professional v4

J2Commerce Professional v4

J2Store/J2Commerce

Description

Free without priority support

 

Specifications

  • Developer J2Store/J2Commerce

Change Log

Fix Fix user delegated tasks fail unauthorized

Fix Cannot remove order items in the cart

Fix Force reload to avoid invalid token on registration

Fix Fix token handling in cart item removal link for mod_j2store_cart

Fix Fix typos in installer script

Improvement Improved CSRF token handling for new module files and update warnings in help.php and the installer script

New Feature Add error handling and logging for defaultPosition and withinArticle methods in j2store content plugin

Fix Fix user delegated tasks fail unauthorized

Fix Cannot remove order items in the cart

Fix Force reload to avoid invalid token on registration

Fix Fix token handling in cart item removal link for mod_j2store_cart

Fix Fix typos in installer script

Improvement Improved CSRF token handling for new module files and update warnings in help.php and the installer script

Fix CVE-2026-78081 Missing CSRF protection on cart, checkout and myprofile controllers

Fix CVE-2026-81567 Blind SQL injection in the storefront product list

Fix CVE-2026-81568 Arbitrary file read via `task=download`

Fix CVE-2026-82189 Any order can be marked Failed by anyone

Fix CVE-2026-82190 Predictable/forgeable order access token

Fix CVE-2026-82191 Unescaped request data reflected into PayPal notify redirect

Fix CVE-2026-78081 Missing CSRF protection on cart, checkout and myprofile controllers

Fix CVE-2026-81567 Blind SQL injection in the storefront product list

Fix CVE-2026-81568 Arbitrary file read via `task=download`

Fix CVE-2026-82189 Any order can be marked Failed by anyone

Fix CVE-2026-82190 Predictable/forgeable order access token

Fix CVE-2026-82191 Unescaped request data reflected into PayPal notify redirect

Fix CVE-2026-77999 Unauthenticated PayPal callback forgery

Fix CVE-2026-78000 Reflected XSS via filter_tag, pricefrom and priceto

Fix CVE-2026-78064 Anonymous cart-record tampering through inherited FOF tasks

Fix CVE-2026-78065 Guest address readable by any registered user

Fix CVE-2026-78069 Apps delegation chain currently shielded by accident

Fix CVE-2026-77999 Unauthenticated PayPal callback forgery

Fix CVE-2026-78000 Reflected XSS via filter_tag, pricefrom and priceto

Fix CVE-2026-78064 Anonymous cart-record tampering through inherited FOF tasks

Fix CVE-2026-78065 Guest address readable by any registered user

Fix CVE-2026-78069 Apps delegation chain currently shielded by accident

Fix CVE-2026-67358 - Quota manipulation

Fix CVE-2026-67359 - Order content disclosure

Fix CVE-2026-67360 - Cross-customer order replication

Fix CVE-2026-67361 - File Upload

Fix CVE-2026-67362 - Open Redirect

Fix CVE-2026-74252 - Guest checkout cookie bypass

Fix

Fix CVE-2026-67358 - Quota manipulation

Fix CVE-2026-67359 - Order content disclosure

Fix CVE-2026-67360 - Cross-customer order replication

Fix CVE-2026-67361 - File Upload

Fix CVE-2026-67362 - Open Redirect

Fix CVE-2026-74252 - Guest checkout cookie bypass

Fix

Fix Cast as char database calls in search plugin

Fix PayPal custom field creates an error

Fix Issues adding images on the product page

Fix Double escaping of tags in the checkout fields

Improvement Modified the FOF message when FOF libraries must be cleaned up on install

Improvement Updated the code with safe DOM methods, escaped variables

Fix Installer plugin loads the wrong URI library

Documentation

Go PRO. Get More Features.

Discount Coupons, Vouchers

Attract more customers and encourage them to buy more with discount coupons, vouchers and more.

Manage Stock Easily

Manage your inventory efficiently with J2Commerce. Do not oversell. Your store can auto-deduct the stock once the customer places a successful order.

Add more tools to your store

Create and send professionally designed emails and invoices to your customers. Add quantity restrictions and much, much more.

What's Changed
  • 4.1.5 - Miscellaneous fixes by @j2commerce in https://github.com/j2commerce/j2cart/pull/299

FIXED Cast as char database calls in search plugin

FIXED PayPal custom field creates an error

FIXED issues adding images on the product page

FIXED double escaping of tags in the checkout fields

MODIFIED the FOF message when FOF libraries must be cleaned up on install

UPDATED the code with safe DOM methods, escaped variables

  • *Full Changelog**: https://github.com/j2commerce/j2cart/compare/v4.1.4...v4.1.5

Stay Updated

Subscribe for free and be the first to know about the latest features, updates, and new additions.